GitLab 已修复 GitLab EE 中的一个漏洞,影响所有 18.7 至 19.2.7 之前版本、19.3 至 19.3.3 之前版本,以及 19.4 至 19.4.1 之前版本。在某些条件下,该漏洞可能导致已认证用户通过 Duo AI 故障排除功能,利用缺失的授权检查,从调试模式作业日志中访问敏感的 CI/CD 变量值。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89078 | 9.9 CRITICAL | Double Free in GitLab |
| CVE-2026-93577 | 9.9 CRITICAL | Integer Overflow or Wraparound in GitLab |
| CVE-2026-92874 | 5.4 MEDIUM | Incorrect Authorization in GitLab |
| CVE-2026-92530 | 4.3 MEDIUM | Use of Less Trusted Source in GitLab |
| CVE-2026-92529 | 4.3 MEDIUM | Incorrect Authorization in GitLab |
| CVE-2026-92628 | 3.1 LOW | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition' |
No comments yet